2025年8月27日星期三

Citrix Products Multiple Vulnerabilities

Citrix Products Multiple Vulnerabilities

Release Date: 27 Aug 2025

RISK: High Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass and remote code execution on the targeted system.

 

Note:

CVE-2025-7775 is being exploited in the wild.  It is a memory overflow bug that can lead to unauthenticated, remote code execution on vulnerable devices.


Devices must be configured in one of the following configurations to be vulnerable:

 

  • NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
  • NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers 
  • NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers
  • CR virtual server with type HDX

 

Hence, the risk level is rated as High Risk.

 

 


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Denial of Service

System / Technologies affected

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-47.48
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-59.22
  • NetScaler ADC 13.1-FIPS and NDcPP before 13.1-37.241-FIPS and NDcPP
  • NetScaler ADC 12.1-FIPS and NDcPP before 12.1-55.330-FIPS and NDcPP

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

思科產品多個漏洞

思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...